SecAlerts
peprodev logo

peprodev

Security Risk Profile

52
/100
medium

Security Risk Score

Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 25, 2023 to present

10
Total CVEs
4
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
52/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
3
Medium
5
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
Infoleak
2
2
XSS
2

Most Affected Products

1. PeproDev Ultimate Profile Solutions3
2. PeproDev Ultimate Invoice2
3. PeproDev WooCommerce Receipt Uploader (WordPress plugin)1
4. Pepro Peprodev Ultimate Invoice Wordpress1
5. PeproDev PeproDev WooCommerce Receipt Uploader1

Recent Vulnerabilities

See more →
CVE-2026-14314
unknown

PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOR

8/6/2026🔧 No Patch
CVE-2026-2343
CVSS 5.3medium

PeproDev Ultimate Invoice <= 2.2.5 - Unauthenticated Invoice Archive Download

3/25/2026🔧 No Patch
CVE-2025-3921
CVSS 8.2EPSS 0%high

PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req Function

5/7/2025🔧 No Patch
CVE-2025-3844
CVSS 9.8EPSS 0%critical

PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Authentication Bypass to Account Takeover

5/7/2025🔧 No Patch
CVE-2025-3924
CVSS 5.3EPSS 0%medium

PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Unauthenticated Email Enumeration

5/7/2025🔧 No Patch
CVE-2024-13719
CVSS 5.3medium

PeproDev Ultimate Invoice <= 2.0.9 - Insecure Direct Object Reference to Unauthenticated Order Information Exposure

2/19/2025🔧 No Patch
CVE-2024-8873
CVSS 6.1EPSS 0%medium

PeproDev WooCommerce Receipt Uploader <= 2.6.9 - Reflected Cross-Site Scripting

11/16/2024🔧 No Patch
CVE-2024-32518
CVSS 5.3EPSS 0%medium

WordPress PeproDev Ultimate Invoice plugin <= 2.0.0 - Broken Access Control vulnerability

4/17/2024🔧 No Patch
CVE-2024-25933
CVSS 7.5EPSS 0%high

WordPress PeproDev Ultimate Invoice plugin <= 1.9.7 - Sensitive Data Exposure vulnerability

3/17/2024🔧 No Patch
CVE-2023-41863
CVSS 7.1high

WordPress PeproDev CF7 Database Plugin <= 1.7.0 is vulnerable to Cross Site Scripting (XSS)

9/25/2023

Monitor peprodev in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

peprodev Security Vulnerabilities & Risk Score | 10 CVEs | SecAlerts - SecAlerts